Privacy & GDPR Policy
How Grappenhall & Widnes Netball Club collects, stores, uses and protects personal information.
- Policy version
- 1.0
- Approved by
- Club Committee
- Effective date
- 01/01/2024
- Review date
- 01/01/2027
On this page
1. Policy Statement
Grappenhall and Widnes Netball Club is committed to protecting the privacy and personal data of all members, volunteers, coaches, officials, parents, carers and supporters.
The Club recognises its responsibilities under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 and is committed to processing personal information fairly, lawfully and transparently.
This policy supports England Netball's commitment to safeguarding personal information and promoting good governance throughout affiliated clubs.
2. Purpose
This policy explains how the Club:
- Collects personal information.
- Stores and protects personal information.
- Uses personal information lawfully.
- Shares information where necessary.
- Ensures individuals understand their rights.
- Responds to data protection requests and breaches.
3. Scope
This policy applies to:
- Club members
- Junior members
- Parents and carers
- Coaches
- Officials
- Volunteers
- Committee members
- Contractors working on behalf of the Club
It applies to all personal data held electronically and in paper format.
4. Data Protection Principles
The Club will ensure that personal data is:
- Processed lawfully, fairly and transparently.
- Collected for specified, legitimate purposes.
- Adequate, relevant and limited to what is necessary.
- Accurate and kept up to date.
- Retained only for as long as necessary.
- Stored securely.
- Protected against unauthorised access, loss or misuse.
5. Personal Data We Collect
The Club may collect:
Members
- Name
- Address
- Date of birth
- Email address
- Telephone number
- Emergency contact details
- Membership number
- Team information
- Playing history
- Attendance records
Junior Members
- Parent or guardian contact details
- Medical information relevant to participation
- Emergency contacts
- Consent forms
Volunteers and Coaches
- Contact details
- Qualifications
- DBS status (where applicable)
- Safeguarding training records
- Coaching qualifications
6. Special Category Data
The Club may process limited special category data including:
- Medical conditions
- Allergies
- Disability information
- Accessibility requirements
This information is collected solely to ensure participants can safely take part in Club activities. Access is restricted to those who need the information.
7. Why We Collect Personal Data
The Club processes information to:
- Register members
- Manage teams and competitions
- Communicate training and fixtures
- Manage memberships
- Administer England Netball affiliation
- Meet safeguarding responsibilities
- Respond to emergencies
- Maintain financial records
- Comply with legal obligations
- Manage volunteers and coaches
- Promote Club activities (where consent has been provided)
8. Lawful Basis for Processing
The Club relies upon one or more of the following lawful bases:
- Consent
- Performance of a contract (membership)
- Legal obligation
- Legitimate interests
- Vital interests (medical emergencies)
Where special category data is processed, the Club will rely on the relevant UK GDPR condition.
10. Photography and Images
Photographs and videos may be used for:
- Club promotion
- Website
- Social media
- Newsletters
Appropriate consent will be obtained where required, particularly for children. Individuals may withdraw consent at any time.
11. Communications
Members may receive information relating to:
- Fixtures
- Training
- Club events
- Membership
- Committee information
- Volunteer opportunities
Marketing communications will only be sent where appropriate consent exists.
12. Data Security
The Club will:
- Password protect electronic records.
- Restrict access to authorised committee members.
- Use secure cloud storage where appropriate.
- Keep paper records securely locked away.
- Dispose of confidential information securely.
- Regularly review access permissions.
13. Data Retention
Personal information will only be retained for as long as necessary. Typical retention periods are:
| Record | Retention period |
|---|---|
| Membership records | Current membership plus 3 years |
| Financial records | 7 years |
| Club shop orders | Personal details removed after 1 year; order record kept 7 years |
| Accident records | 7 years (or longer where required) |
| Safeguarding records | In accordance with safeguarding guidance |
| DBS information | Not retained beyond permitted checks |
| Coaching qualifications | Duration of volunteering plus 3 years |
Records will be securely destroyed when no longer required.
14. Individual Rights
Individuals have the right to:
- Be informed.
- Access their personal data.
- Correct inaccurate information.
- Request deletion where appropriate.
- Restrict processing.
- Object to processing.
- Request transfer of data where applicable.
- Withdraw consent.
Requests should be made in writing to the Club Secretary or a Data Protection Lead. The Club aims to respond within one calendar month.
15. Data Breaches
A personal data breach includes:
- Loss of personal information.
- Theft of records.
- Unauthorised disclosure.
- Hacking or cyber incidents.
- Sending information to the wrong recipient.
Any suspected breach must immediately be reported to the Club Chair or a Data Protection Lead. The Club will:
- Assess the risk.
- Record the breach.
- Take immediate action.
- Notify the Information Commissioner's Office (ICO) where legally required.
- Inform affected individuals where appropriate.
16. Responsibilities
Committee
The Committee is responsible for ensuring compliance with this policy.
Club Secretary / Data Protection Leads
Responsible for:
- Maintaining secure records.
- Managing data requests.
- Recording breaches.
- Advising the Committee.
- Ensuring compliance.
Data Protection Leads
Bethany Keen
Emma Whiteside
A request or a concern can go to either of them.
Coaches and Volunteers
All volunteers must:
- Protect personal information.
- Only access information necessary for their role.
- Keep passwords secure.
- Report breaches immediately.
- Follow Club procedures.
17. Use of Email and Messaging Apps
When communicating with members:
- Personal email addresses will not be shared unnecessarily.
- Group messaging should protect individuals' privacy where possible.
- Parents should be included in communications with junior members.
- Personal information should not be shared via social media.
18. Online Meetings
Where online meetings are used:
- Appropriate security settings will be enabled.
- Only invited participants may attend.
- Meetings involving juniors should follow the Club Safeguarding Policy.
20. Complaints
Anyone who believes their personal data has been mishandled should contact the Club Secretary or a Data Protection Lead in the first instance.
If concerns cannot be resolved, individuals have the right to complain to the Information Commissioner's Office (ICO).
21. Policy Review
This policy will be reviewed:
- Annually.
- Following changes to legislation.
- Following significant data breaches.
- Following changes to England Netball guidance.
Policy Approval
Approved by: Bethany Keen
Chair: Meg Parker
Signature: B.Keen & M.Parker
Date: 01/01/2026
Club Secretary / Data Protection Lead: Bethany Keen
Signature: B.Keen